Most headlines about ransomware focus on the same handful of household names, but a quieter category of threat actors is proving just as damaging. Lesser-known ransomware groups are increasingly abandoning the sprawling affiliate networks that made groups like LockBit and Cl0p infamous, opting instead for small, disciplined teams that are harder to infiltrate and harder to predict. Royal, a group that emerged around September, is one of the clearest examples of this shift, and it offers a useful case study in why smaller doesn't mean safer for the businesses these groups target.

A Different Business Model: Closed Crews Over Affiliates

Most major ransomware operations run on an affiliate, or ransomware-as-a-service, model. The core developers build and maintain the malware, then license it out to a rotating cast of affiliates who carry out the actual intrusions in exchange for a cut of the ransom. It's an efficient structure that lets a single piece of malware scale across dozens or hundreds of simultaneous attacks, but it also creates weak points. Affiliates get sloppy, leak details, or get arrested, and law enforcement has had real success unraveling these networks by chasing the loosest link.

Royal skips that model entirely. Rather than recruiting a wide affiliate base, the group operates with a smaller, tighter core team believed to include former members of Conti, one of the most prolific and technically sophisticated ransomware operations before it splintered. That pedigree matters. A group built around experienced operators who already know how to move through corporate networks, evade detection, and negotiate ransoms doesn't need scale to be effective. It needs discipline, and a closed structure is easier to keep disciplined.

For defenders, this is a meaningful change in the threat landscape. Affiliate-driven groups often leave a trail of inconsistent tactics because so many different people are using the same toolkit. A closed crew like Royal, by contrast, tends to operate with more consistency and more operational security, which can make its activity harder to fingerprint and attribute in the early stages of an intrusion.

Double Extortion Remains the Common Thread

Despite the structural differences, Royal shares one tactic with nearly every other active ransomware group today: double extortion. Instead of simply encrypting a victim's files and demanding payment for a decryption key, the group first exfiltrates sensitive data from the network. If the ransom isn't paid, the threat isn't just locked files, it's the public release of stolen data, which can include customer records, financial information, or internal communications.

This two-pronged pressure campaign has become the industry standard because it works. Even organizations with solid backup systems that could restore encrypted data without paying still face the reputational and regulatory fallout of a data leak. It's a tactic that shows up across the ransomware ecosystem regardless of a group's size or notoriety. Smaller, newer entrants use it just as readily as established names. The recent case of M3RX ransomware claiming a Spanish software firm and stealing hundreds of gigabytes of data follows the same playbook: infiltrate, exfiltrate, encrypt, and threaten exposure until payment is made.

What this pattern tells businesses is that the size or fame of a ransomware group is a poor proxy for risk. A relatively unknown crew with a handful of skilled operators can execute the same double-extortion attack, with the same consequences, as a group that dominates headlines.

What This Means For You

For security teams and business owners, the lesson from Royal and similar groups is that threat monitoring built around watching a short list of famous ransomware names is incomplete. Lesser-known ransomware groups are frequently staffed by experienced operators from disbanded or rebranded organizations, meaning their capabilities can rival those of bigger names even without a large public footprint.

This also has direct implications for how organizations think about network access. Because double extortion depends on attackers being able to move through a network and pull out data before triggering encryption, limiting lateral movement is one of the most effective defenses available. Strong network segmentation, strict access controls, and monitoring for unusual outbound data transfers can catch an intrusion before exfiltration completes, even if the initial breach isn't stopped. Secure remote access tools, including properly configured VPNs with multi-factor authentication, remain one of the simplest ways to reduce the exposed attack surface that groups like Royal rely on to gain an initial foothold.

Actionable Takeaways

Businesses don't need to track every obscure ransomware group by name to protect themselves, but they do need to assume that any unpatched system or exposed remote access point is a potential entry for groups they've never heard of. A few practical steps make a real difference: keep remote access tools patched and behind multi-factor authentication, segment networks so a single compromised account can't reach sensitive data, monitor for large or unusual outbound data transfers that could indicate exfiltration in progress, and maintain offline backups that are tested regularly, not just stored.

Lesser-known ransomware groups aren't a footnote to the bigger names dominating the news. As Royal and other smaller, closed-crew operations demonstrate, reduced visibility often comes with increased operational skill, not decreased risk. Treating every group, familiar or not, with the same level of defensive rigor is the most reliable way to stay ahead of them.